GHSA-mmhr-3jr7-qj2p · Severity: high · Ecosystem: nuget — Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Conclusion & alert: CVE-2018-15121 is rated Moderate Risk (48.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.49%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.07% | 0.49% | +0.41% |
| 2 | 2023-03-07 | 0.89% | 0.07% | -0.81% |
| 3 | 2022-02-04 | — | 0.89% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-mmhr-3jr7-qj2p · Severity: high · Ecosystem: nuget — Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| auth0 | aspnet | — | cpe:2.3:a:auth0:aspnet:-:*:*:*:*:*:*:* |
| auth0 | aspnet-owin | — | cpe:2.3:a:auth0:aspnet-owin:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://auth0.com/docs/security/bulletins/cve-2018-15121 | Vendor Advisory |